Skip to main content
theengineer
New Member
July 23, 2020
Question

IPSEC Phase 1 and Phase 2 is up but return traffic not observed on Fortigate

  • July 23, 2020
  • 3 replies
  • 3202 views

Hi,

 

Issue is as above. Peering firewall is a Cisco Firepower.

Site A - FW A (Fortigate) <IPSEC tunnel> FW B (Cisco Firepower) - Site B

 

IPSEC P1, P2 is up and green. We're attempting SSH to reach Site B machine from Site A. We are seeing the traffic leaving from site A, routed through the tunnel interface via a diagnose sniffer packet, and from the Site B machine tcpdump we are seeing the Syn traffic reaching the machine and return traffic sent. FW B's administrator is seeing the return traffic from Site B as well and forwards it back to Site A, but we're not seeing the traffic on Fortigate (FW A) and causing a timeout of the SSH attempt either from diagnose sniffer packet, network capture from the Fortigate or a diagnose debug flow. 

 

I've been scratching my head and not too sure on what's the next step I could take, so any feedback or questions is appreciated.

 

Thanks in advance.

    3 replies

    darthro132
    New Member
    June 3, 2022

    We had the same issue, I worked with Fortinet support and tech support for the other side and we couldn't figure it out either.  What we ended up doing was migrating the tunnel off of our secondary ISP to our Primary and it came up.

    ntaneja
    Staff & Editor
    Staff & Editor
    June 4, 2022

    Hi theengineer

     

    Please run sniffer for both side public IP address and check if you see in and out esp packets on FGT A.
    It's possible that ISP on site A FGT which is used to bind this vpn tunnel is blocking incoming esp traffic.


    Thanks

    Vichu_94
    Staff
    Staff
    June 4, 2022

    Hi @theengineer,

     

    Are you able to do ssh if the traffic is being initiated from Site B side? Is the flow of traffic same.

     

    Please take a wireshark capture on FGT by initiating the traffic from Site A.

    diag snif packet any 'host <remote_side_public_ip> and esp' 6 0 l

     

    Also take the wireshark capture on both the end.

     

    Please share the output cmd of phase2 selectors:-

    diag vpn tunnel list name <Phase1_name>

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!